Sub Command Teacher Guide Sub Command Guide
Project: Cyber Breach Protocol
Cyber Security 2
Duration: 2 Days
Project Overview
Students are returning from Spring Break and starting a 2-day independent project on the Five Phases of Penetration Testing . They will act as "Ethical Hackers" tasked with researching each phase and creating a visual deliverable (either a digital slide deck or a physical research poster).
Key Learning Goal
Identify and describe: Reconnaissance, Scanning, Gaining Access, Maintaining Access, and Covering Tracks.
Student Output
A 5-part visual guide (Poster or Slides) explaining each phase with real-world tool examples.
Two-Day Battle Plan
Day 1: Research & Recon
Students receive the Breach Blueprint Project Guide and Hacker Toolkit Reference Sheet .
Task: Research the 5 phases of ethical hacking.
Goal: Complete the "Planning Zone" on the second page of their guide. This is their rough draft.
Check-in: By class end, students should have at least 3 tools identified.
Day 2: Production & Deployment
Students transition research into final format (Poster or Slides).
Digital: Using Google Slides, PowerPoint, or Canva.
Physical: Using poster board/paper and markers.
Goal: Submit final project and the completed Project Guide/Rubric for grading.
Substitute Pro-Tips
Common Roadblock: "I can't find tools!"
Direct them to the Hacker Toolkit Reference Sheet . It lists common tools like Nmap and Metasploit to get them started.
Pacing Check
If a student is stuck on Day 2, they likely missed the "Planning Zone" step on Day 1. Have them show you their written outline.
Classroom Kit Checklist
Breach Blueprint Project Guide
Hacker Toolkit Reference Sheet
Cyber Ops Project Rubric
Markers, Poster Paper, Laptops
Breach Blueprint Project Guide Breach Blueprint
Protocol: Ethical Hacking Phases Project
NAME: ___________________________
DATE: ___________________________
STATUS: UNKNOWN
Mission Objective
You are an Ethical Hacker returning from leave. A major corporation has hired you to perform a "white-hat" security audit. To secure the contract, you must present a detailed **Visual Security Brief** explaining the 5 Phases of Penetration Testing you will use to find their vulnerabilities.
Deliverable Requirements
Format Choices
Digital: Slide Deck (Min. 7 slides)
Physical: Research Poster (Large format)
Content Per Phase
Title of Phase
Clear definition (Your own words)
At least ONE specific tool used
One visual (Icon or Screenshot)
Required Phases to Cover
01 Recon
02 Scanning
03 Gaining
04 Maintaining
05 Covering
Day 1 Planning Zone
Complete this outline before starting your final production.
01: Reconnaissance (Active vs Passive)
02: Scanning (Tools & Target Mapping)
03: Gaining Access
04: Maintaining Access
05: Covering Tracks
Final Project Layout Sketch (Poster or Slide Plan) Hacker Toolkit Reference Sheet Hacker Toolkit
Essential Reference: The 5 Phases of Penetration Testing
Phase 1: Reconnaissance
LEVEL_01
Gathering as much information as possible about the target organization. This includes public data, network ranges, and employee details.
Note: Passive recon doesn't touch target systems; active recon does.
Industry Tools
WHOIS Lookups
Shodan.io
TheHarvester
Google Dorks
Phase 2: Scanning
LEVEL_02
Scanning tools are used to find open ports, live systems, and specific services. This phase maps the "attack surface" and identifies potential vulnerabilities.
Industry Tools
Nmap
Nessus
OpenVAS
Wireshark
Phase 3: Gaining Access
LEVEL_03
Exploiting vulnerabilities found in Phase 2 to enter the system. This could involve bypassing login screens, injecting code, or social engineering.
Industry Tools
Metasploit
Burp Suite
SQLMap
BeEF Framework
Phase 4: Maintaining Access
LEVEL_04
Ensuring the hacker can return later. This involves setting up persistent connections like backdoors or hidden administrative accounts.
Industry Tools
Netcat
Persistent Backdoors
Remote Access Tools
Phase 5: Covering Tracks
LEVEL_05
Hiding the presence of the attack to avoid detection by IT security or forensic teams. Includes deleting logs and removing temp files.
Common Tactics
Log Scrapping
Steganography
Removing History
REMINDER: Unauthorized access to computer systems is illegal. For educational use only.
Cyber Ops Rubric Cyber Ops Rubric
Project Evaluation: Pentesting Lifecycle
TOTAL: / 100
Criteria Exceeds (20-18 pts) Meets (17-15 pts) Developing (14-0 pts) Phase 1: Recon Distinguishes between active/passive; names 2+ advanced tools. Defines phase clearly; names 1 tool. Vague definition or missing tools. Phase 2: Scanning Explains port/vulnerability scanning; provides Nmap/Nessus examples. Explains basic scanning; names 1 tool. Misunderstands scanning purpose. Phase 3: Gaining Access Provides specific exploitation methods (SQLi, Phishing, etc). Basic definition of exploitation. Missing clear tool or method. Phase 4-5: Persistence Detailed look at backdoors and log scrubbing techniques. Basic definition of maintenance and covering tracks. Missing one of the two phases. Visual Design Professional look, logical flow, used icons/images effectively. Neat and readable; used basic visuals. Cluttered, hard to read, or no visuals.
Teacher Feedback
Strength
Example: "Great use of real-world tool examples in the scanning section."
Growth Area
Example: "Try to explain 'Persistence' in simpler terms next time."
North Carolina CTE Cyber Security II - Standard Alignment: CS02.04
Mission Briefing Slides Mission Briefing
PROTOCOL: CYBER BREACH PROJECT
Cyber Security 2 Self-Guided Mission
The Scenario
A major tech firm has been hit. They've hired YOU to map out the attack lifecycle.
Primary Objective:
Research and present the 5 Phases of Penetration Testing so the board of directors understands how they were breached.
The Pentesting Lifecycle
01
Recon
Gathering Intelligence
02
Scanning
Target Mapping
03
Access
Exploitation
04
Maintain
Persistence
05
Covering
Ghost Protocol
Required Deliverables
Phase Intel
Define each phase in your own words. Use your Hacker Toolkit reference sheet for support.
Weapon Selection
Identify ONE real-world tool (e.g., Nmap, Metasploit) used in each of the 5 phases.
Option A: Poster
A physical infographic. Use markers and provided poster board.
Option B: Slide Deck
A professional digital deck. Minimum 7 slides total.
Day 1: Status Check
01
Obtain the Breach Blueprint Project Guide.
02
Research all 5 phases using the Hacker Toolkit reference.
03
Complete the Planning Zone outline on page 2.
SYSTEMS ONLINE. COMMENCE RECONNAISSANCE.